← Vulnerability feed

Vulnerability record · CVE-2014-6593 · published 21 January 2015

CVE-2014-6593: Oracle Java JSSE flaw allows remote confidentiality and integrity impact

Oracle · Jrockit

CVE-2014-6593 is an unspecified vulnerability in the JSSE component of Oracle Java SE (5.0u75, 6u85, 7u72, 8u25), Java SE Embedded (7u71, 8u6) and JRockit (27.8.4, 28.3.4). Oracle's advisory and the record give no technical detail on the root cause, but the flaw is remotely reachable and affects both confidentiality and integrity. It matters because JSSE underpins TLS in Java, so any weakness there can undermine the security of Java-based network communications.

4.0 CVSS 2.0 Medium EPSS 66% · top 0.7%
4.0CVSS 2.0 base score
66%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
54References
17 Jun 2026Last modified by NVD

Description

Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25; Java SE Embedded 7u71 and 8u6; and JRockit 27.8.4 and 28.3.4 allows remote attackers to affect confidentiality and integrity via vectors related to JSSE.

AV:N/AC:H/Au:N/C:P/I:P/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

medium priorityCVSS v2 rates it MEDIUM (4.0) with high access complexity and no confirmed exploitation, but the high EPSS score and broad Java deployment warrant timely patching.

What it is

CVE-2014-6593 is an unspecified vulnerability in the JSSE component of Oracle Java SE (5.0u75, 6u85, 7u72, 8u25), Java SE Embedded (7u71, 8u6) and JRockit (27.8.4, 28.3.4). Oracle's advisory and the record give no technical detail on the root cause, but the flaw is remotely reachable and affects both confidentiality and integrity. It matters because JSSE underpins TLS in Java, so any weakness there can undermine the security of Java-based network communications.

Impact

A remote attacker can affect the confidentiality and integrity of data handled by the affected Java runtime, potentially reading or altering information protected by JSSE. No code execution or availability impact is stated in the record.

Attack surface

The CVSS v2 vector AV:N/AC:H/Au:N/C:P/I:P/A:N indicates the flaw is reachable over the network with no authentication required, but exploitation is difficult due to high access complexity. No user interaction is specified in the record.

Exploitation

The record is not listed in CISA KEV and no reference carries an exploit tag, so confirmed in-the-wild exploitation is not established; EPSS is high (0.66374, 99.2nd percentile), indicating elevated predicted exploitation likelihood.

What to do

  • Apply the Oracle Critical Patch Update January 2015 fixes for Java SE, Java SE Embedded and JRockit, or the corresponding vendor updates (Red Hat, Debian, Ubuntu, SUSE, Gentoo, HP, VMware, McAfee).
  • Upgrade to a Java release newer than the affected versions listed (5.0u75, 6u85, 7u72, 8u25, Embedded 7u71/8u6, JRockit 27.8.4/28.3.4).
  • Inventory Java and JRockit installations across servers and endpoints and confirm none remain on the affected builds.
  • Where Java is not required, remove it or restrict network exposure of Java-based services to reduce the attack surface.

Detection

  • Search asset inventories and vulnerability scans for Java/JRockit versions matching the affected builds.
  • Monitor network traffic to and from Java-based services for anomalous TLS/JSSE behavior, though the record provides no specific signature.
  • Review vendor patch and package management logs to confirm JSSE-related Java updates were applied.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://h20564.www2.hp.com/hpsc/doc/public/display?docId=emr_na-c04583581
http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00001.html
http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00024.html
http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00018.html
http://marc.info/?l=bugtraq&m=142496355704097&w=2
http://marc.info/?l=bugtraq&m=142607790919348&w=2
http://packetstormsecurity.com/files/134251/Java-Secure-Socket-Extension-JSSE-SKIP-TLS.html
http://rhn.redhat.com/errata/RHSA-2015-0068.html
http://rhn.redhat.com/errata/RHSA-2015-0079.html
http://rhn.redhat.com/errata/RHSA-2015-0080.html
http://rhn.redhat.com/errata/RHSA-2015-0085.html
http://rhn.redhat.com/errata/RHSA-2015-0086.html
http://rhn.redhat.com/errata/RHSA-2015-0136.html
http://rhn.redhat.com/errata/RHSA-2015-0264.html
http://www.debian.org/security/2015/dsa-3144
http://www.debian.org/security/2015/dsa-3147
http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html PatchVendor Advisory
http://www.securityfocus.com/bid/72169
http://www.securitytracker.com/id/1031580
http://www.ubuntu.com/usn/USN-2486-1
http://www.ubuntu.com/usn/USN-2487-1
http://www.vmware.com/security/advisories/VMSA-2015-0003.html
https://kc.mcafee.com/corporate/index?page=content&id=SB10104
https://security.gentoo.org/glsa/201507-14
https://security.gentoo.org/glsa/201603-14
https://www-304.ibm.com/support/docview.wss?uid=swg21695474
https://www.exploit-db.com/exploits/38641/
http://h20564.www2.hp.com/hpsc/doc/public/display?docId=emr_na-c04583581
http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00001.html
http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00024.html
http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00018.html
http://marc.info/?l=bugtraq&m=142496355704097&w=2
http://marc.info/?l=bugtraq&m=142607790919348&w=2
http://packetstormsecurity.com/files/134251/Java-Secure-Socket-Extension-JSSE-SKIP-TLS.html
http://rhn.redhat.com/errata/RHSA-2015-0068.html
http://rhn.redhat.com/errata/RHSA-2015-0079.html
http://rhn.redhat.com/errata/RHSA-2015-0080.html
http://rhn.redhat.com/errata/RHSA-2015-0085.html
http://rhn.redhat.com/errata/RHSA-2015-0086.html
http://rhn.redhat.com/errata/RHSA-2015-0136.html

Track CVE-2014-6593 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2016-3427Oracle Java SE JMX Improper Access Control VulnerabilityCVE-2016-3427 is an unspecified vulnerability in Oracle Java SE 6u113, 7u99, 8u77, Java SE Embedded 8u77, and JRockit R28.3.9, reached through vector…KEVEPSS 92%analysed9.8CVE-2015-2590Oracle Java SE Libraries flaw allows remote code executionCVE-2015-2590 is an unspecified vulnerability in the Libraries component of Oracle Java SE 6u95, 7u80, 8u45 and Java SE Embedded 7u75, 8u33. The reco…KEVEPSS 25%analysed9.8CVE-2013-2465Oracle Java SE JRE 2D sandbox bypass and code executionCVE-2013-2465 is an unspecified vulnerability in the 2D component of Oracle Java SE JRE (7 Update 21 and earlier, 6 Update 45 and earlier, 5.0 Update…KEVEPSS 99%analysed9.8CVE-2013-0422Oracle Java 7 JMX/MBean and Reflection API sandbox bypass RCEOracle Java 7 before Update 11 contains two flaws: the public getMBeanInstantiator method in JmxMBeanServer exposes a private MBeanInstantiator that …KEVEPSS 97%analysed9.8CVE-2012-5076Oracle Java SE JRE JAX-WS sandbox bypassCVE-2012-5076 is an unspecified vulnerability in the Java Runtime Environment (JRE) component of Oracle Java SE 7 Update 7 and earlier, related to JA…KEVEPSS 91%analysed9.8CVE-2012-4681Oracle Java SE 7 JRE SecurityManager bypass allows remote code executionThe Java Runtime Environment in Oracle Java SE 7 Update 6 and earlier fails to properly enforce SecurityManager restrictions. A crafted applet can us…KEVEPSS 99%analysed9.8CVE-2012-1723Oracle Java SE Hotspot Improper Access Control Enables Remote Code ExecutionCVE-2012-1723 is an unspecified vulnerability in the Hotspot component of Oracle Java SE (JRE) affecting Java SE 7 update 4 and earlier, 6 update 32 …KEVEPSS 94%analysed9.8CVE-2012-0507Oracle Java SE JRE AtomicReferenceArray type confusion sandbox bypassCVE-2012-0507 is an unspecified vulnerability in the Java Runtime Environment (JRE) Concurrency component affecting Java SE 7 Update 2 and earlier, 6…KEVEPSS 98%analysed

Source: NIST National Vulnerability Database (record CVE-2014-6593), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.